← SecureAZ Blog

Phishing · 6 min read · Published 23 April 2026 · Reviewed 17 August 2026

IRD Refund Phishing Emails NZ: What to Look For and How to Report

Fake IRD refund emails spike every NZ tax season. Here's what these phishing emails look like, why they're convincing, and what your staff need to know to avoid them.

Every New Zealand tax season, the same wave arrives in inboxes across the country: emails claiming to be from Inland Revenue, informing the recipient of a pending tax refund. The only thing standing between the scammer and a successful credential harvest is whether the recipient knows what to look for.

According to CERT NZ, tax-themed phishing campaigns are consistently among the highest-volume email scams reported in New Zealand, spiking between April and July each year. The campaigns are increasingly convincing — with accurate IRD branding, plausible refund amounts, and login pages that are nearly indistinguishable from the real myIR portal.

What a fake IRD refund email looks like

Modern IRD phishing emails have moved well beyond the crude "Dear Customer" format of a decade ago. Current campaigns typically include:

  • Accurate IRD logo and branding — scraped directly from the real IRD website
  • A personalised greeting — often using your actual name, sourced from data breaches
  • A plausible refund amount — usually $200–$900, specific enough to feel real
  • An urgency trigger — "Your refund will expire in 7 days" or "Action required before 30 June"
  • A single call-to-action button — "Claim Your Refund" or "Verify Your Details"

The button links to a cloned myIR login page. When you enter your credentials, two things happen: the scammer captures your username and password, and you're usually redirected to the real myIR site — so you never realise anything went wrong.

Why these emails are so effective

Three factors make IRD refund phishing unusually successful:

Timing — Everyone expects something from IRD at tax time. An email arriving in May or June doesn't feel out of place.

Positive framing — Unlike threat-based scams ("your account has been suspended"), a refund offer triggers positive anticipation rather than alarm. Positive emotion reduces critical thinking.

Familiarity — Most New Zealanders interact with myIR annually. The login page looks exactly as expected, which bypasses the visual suspicion triggers that would flag an unfamiliar interface.

The technical tells your staff should know

Even well-crafted IRD phishing emails leave traces if you know where to look:

Check the sender address — Real IRD emails come from '@ird.govt.nz'. Hover over the sender name (don't just read the display name) and look at the actual address. Scam emails use addresses like 'refunds@nz-ird.com', 'inland.revenue@taxrefund.net', or spoofed addresses that require careful reading to spot.

Inspect the link before clicking — Hover over the button or link and look at the URL that appears in the status bar. The real myIR portal is at 'myir.ird.govt.nz'. Anything else — including convincing-looking domains like 'myir-ird.nz' or 'ird-portal.govt-nz.com' — is a scam.

IRD never emails refund notifications — The real process: IRD calculates your refund, it appears in myIR, and you're notified by email that there's a message in your myIR inbox. IRD does not email you the refund amount or ask you to click a link to claim it. If an email contains a refund amount and a claim link, it is a scam.

Check the greeting — Real IRD communications address you by your legal name as registered in the system. "Dear IRD Customer" or "Dear Taxpayer" is an immediate red flag.

What happens if someone clicks

The immediate risk is credential compromise — the attacker now has the myIR login details. What they do with those credentials depends on the campaign:

  • Identity fraud — Changing bank account details in myIR to redirect genuine future refunds
  • Tax fraud — Filing false returns using the victim's IRD number
  • Credential stuffing — Testing the same username/password against banking apps, email, and other services (password reuse is extremely common)
  • Account takeover — Using the myIR account to access personal tax history, which can enable further identity fraud

For business owners, the stakes are higher. A compromised myIR account that has employer registration access can expose employee IRD numbers, PAYE records, and filing history.

What to do if you suspect a click has occurred

  1. Go directly to myIR — Type 'myir.ird.govt.nz' directly into your browser (don't use any links)
  2. Change your password immediately
  3. Check recent myIR activity — Look for any changes to bank account details or contact information
  4. Contact IRD directly — Call 0800 227 774 to report suspected compromise and request a security review
  5. Report to CERT NZcert.govt.nz/report — reporting helps CERT NZ track and disrupt active campaigns
  6. Notify IT — If this happened on a work device or work email account, your IT team needs to know immediately

Training staff before tax season

The most effective intervention is a pre-season phishing simulation using an IRD refund template, delivered in late March or early April — before the real campaigns start arriving. Employees who encounter a safe simulated version of the attack are significantly more likely to recognise and report the real thing.

See our post on SMS-based MFA and why it's not enough — relevant because credential harvesting via phishing is one of the primary ways attackers bypass SMS 2FA.

SecureAZ includes IRD-branded phishing simulation templates updated for each tax season. Start a free trial and run your first simulation before the April peak.